Proofed once at registration, stolen at the dock: the 2026 cargo theft arithmetic
Two numbers from 2026 sit awkwardly together. Cargo theft incidents fell twenty-six percent year over year. Losses more than doubled, to $304.6 million in a single quarter. Fewer thefts, bigger losses — and the explanation is that the industry hardened the front door while the money walks out of the loading dock.
Why did cargo thefts fall while losses more than doubled?
Because the control moved to registration and the attack moved to the dock. FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers. Fewer, better-targeted thefts of higher-value loads is what you get when you proof once and never again.
- FMCSA identity proofing took effect in January 2026: government photo ID and a live facial selfie to obtain operating authority. It addresses registration, which is not where the losses occur.
- The FBI's IC3 reported 2025 cargo theft losses of approximately $725 million, a 60% increase, driven by cyber-enabled strategic theft.
- Across eleven lifecycle moments from registration to delivery, nine inherit identity rather than establish it. Three deserve a cryptographic re-proof.
Part of Freight, cargo and customs identity
What changed in registration, and when
In January 2026 the Federal Motor Carrier Safety Administration implemented identity proofing for new carrier and broker applications, requiring a government-issued photo identification and a live facial selfie. MC numbers were retired in the same period, consolidating identification on the USDOT number. In May 2026 a modernised registration system launched, described by the Department as improving fraud detection and data quality.
These are substantive changes and they were correctly motivated. Registration fraud — obtaining authority under a fabricated or stolen identity — was a real and growing problem, and the controls address it directly.
What the loss data did in the same period
The FBI's Internet Crime Complaint Center issued a public service announcement on 30 April 2026 on cyber-enabled strategic cargo theft, reporting that estimated 2025 losses in the United States and Canada reached approximately $725 million — roughly a 60% increase over 2024.
Industry data through 2026 continued the pattern. Reported incidents in the second quarter fell about 26% year over year, while estimated losses in that quarter reached $304.6 million against $135.7 million a year earlier. Earlier in the year, more than 1,120 incidents with roughly $121 million in losses were recorded across the first five months.
| Metric | Direction in 2026 | Implication |
|---|---|---|
| Incident count | Down ~26% year over year | Fewer, more selective operations |
| Loss total | More than doubled | Higher value per incident |
| Implied value per incident | Up sharply | Targets are being selected, not encountered |
| Method | Shift toward strategic and cyber-enabled theft | Identity, not force |
Why hardening registration does not move those numbers
Strategic cargo theft does not begin with obtaining authority. It begins with impersonating authority that already exists — a legitimate carrier's USDOT number, a real insurance certificate, a plausible email domain, a dispatcher who answers the phone.
Identity proofing at registration raises the cost of creating a new fraudulent carrier. It does nothing about presenting the credentials of an existing legitimate one, which is both cheaper and more effective because the attributes survive every downstream check.
A check performed once, years ago, against a person who is not the one standing at your dock, is not a check.
The Freight Identity Lifecycle Map
Eleven moments between registration and delivery. For each, whether identity is established (proven at that moment), inherited (carried forward from an earlier proof), or asserted (claimed with no verification).
| # | Moment | Identity state | Loss concentration |
|---|---|---|---|
| 1 | Operating authority registration | Established | Low |
| 2 | Load board posting and search | Asserted | Low |
| 3 | Carrier onboarding by broker | Inherited (attributes checked) | Moderate |
| 4 | Rate confirmation issued | Asserted | Moderate |
| 5 | Re-tender to another carrier | Asserted | High |
| 6 | Driver assignment | Asserted | Moderate |
| 7 | Arrival and gate check-in | Asserted | High |
| 8 | Dock release of freight | Asserted | Highest |
| 9 | In-transit status updates | Asserted | Low |
| 10 | Delivery and proof of delivery | Asserted | Moderate |
| 11 | Settlement and payment | Inherited | Moderate |
Nine of eleven inherit or assert. The three carrying the highest loss concentration — re-tender, gate check-in and dock release — are all pure assertion, verified by document inspection.
The three moments worth a cryptographic re-proof
- Re-tender (moment 5). Express permitted co-brokerage as a delegation with an explicit depth limit, so an unauthorised re-tender is detectable rather than discoverable at claim time.
- Gate check-in (moment 7). The driver presents a signed assertion under a load-bound delegation, not a rate confirmation PDF.
- Dock release (moment 8). The shipper verifies the assertion offline against a published key before releasing freight.
Each is a single point in an existing workflow. None requires a new system in the freight path, and all three verify without connectivity — which matters at a dock in an industrial park.
Reading the numbers carefully
Incident counts and loss totals differ between IC3, industry databases and insurer datasets because inclusion criteria differ — some count attempts, some count only confirmed thefts, some include in-transit pilferage. This article cites each source with its own figure rather than selecting the largest, and the per-incident implied value used above derives from the quarterly industry data cited, not from a national average.
What none of the datasets disagrees about is the direction: value per incident is rising sharply, and the method producing that rise is identity-based.
What the two numbers together mean
A falling count with rising losses is the signature of a control that raised the cost of entry. Casual thieves were priced out; the ones who remain target fewer, larger loads and invest more per attempt. That is a real improvement in one dimension and a worsening in another, and reporting either number alone misleads.
| Stage | Gate today |
|---|---|
| Registration | Strong, since January 2026 |
| Account access | Password and sometimes MFA |
| Load acceptance | None — a tender in a system |
| Pickup | Paperwork |
Objections and honest limits
“So registration hardening failed.” It did not. It removed a class of attacker, which is what the falling count shows. It simply cannot reach the dock, which is where the remaining loss concentrates.
“Identity re-proofing at every pickup is impractical.” It is. Re-proofing is not the same as re-authorising — a signature bound to this tender takes seconds and does not re-run identity verification.
Closing the lifecycle gap
- Treat registration and pickup as separate gates. They answer different questions.
- Bind the tender to a credential at acceptance. When the carrier takes the load, not at the dock.
- Verify that binding at pickup. Seconds, fail closed.
- Re-affirm carrier identity periodically. Not per load — per quarter is enough to catch account takeover.
Terms used here
- Operating authority
- The federal grant permitting a carrier to operate, now subject to photo ID and live selfie proofing.
- Double brokering
- Re-tendering a load to another carrier without authority, which breaks the chain of custody and insurance.
- Strategic theft
- Theft using assumed identity and documentation rather than force — the category that grew.
Frequently asked questions
Did FMCSA's changes make things worse? No. They addressed registration fraud, which was a genuine problem. The point is that the losses concentrate elsewhere in the lifecycle, so improvement at registration was never going to move the loss numbers.
Is this just fictitious pickup? Fictitious pickup is the dominant technique at moment 8. Moments 5 and 7 involve related but distinct methods — unauthorised re-tender and driver impersonation — which is why they are separated.
What does a dock actually do differently? It stops evaluating documents and starts verifying a signature against a published key. The verification is offline and takes under a second.
Does this require every carrier to adopt something? For a given lane, it requires the broker and the shipper to agree and the carrier's driver to hold a credential. It works bilaterally before it works industry-wide.
Why did losses rise while thefts fell? Registration hardening priced out casual thieves. Those remaining target fewer, higher-value loads and invest more per attempt.
Is re-proofing needed at every pickup? No. Re-authorising is not re-proofing. A signature bound to this tender takes seconds and does not repeat identity verification.
Where is the remaining gap? Between load acceptance and pickup, where nothing re-establishes that the collector is the carrier that accepted.
Where this fits in Manav
Manav binds the authorising person to the exact release, tender or instruction, and produces a receipt a shipper, a terminal or a broker can verify at the gate without a phone call.